2026 CVE Vulnerabilities

44,815 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-45628CRITICAL9.6Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands ...
CVE-2026-45625CRITICAL9.9Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-bas...
CVE-2026-48501CRITICAL9.1GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization h...
CVE-2026-45663CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability ...
CVE-2026-44962CRITICAL9.9Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied...
CVE-2026-10064CRITICAL9.8A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetPortTr of the file ...
CVE-2026-4290CRITICAL9.1The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-gui...
CVE-2026-10063CRITICAL9.8A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the fil...
CVE-2026-10062CRITICAL9.8A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRou...
CVE-2026-10042CRITICAL9.8manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deseri...
CVE-2026-46376CRITICAL9.8FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access...
CVE-2026-10061CRITICAL9.8A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. ...
CVE-2026-10060CRITICAL9.8A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /gofor...
CVE-2026-9508CRITICAL10Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow bac...
CVE-2026-8326CRITICAL10Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitra...
CVE-2026-45312CRITICAL9.9RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injectio...
CVE-2026-45043CRITICAL9.3RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rust...
CVE-2026-10071CRITICAL9.8DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers ...
CVE-2026-9559CRITICAL9.9A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files dur...
CVE-2026-9558CRITICAL9.9A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twi...
CVE-2026-49201CRITICAL9.8The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows a...
CVE-2026-49200CRITICAL9.8The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file conta...
CVE-2026-49199CRITICAL9.8Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.
CVE-2026-49197CRITICAL9.8Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requ...
CVE-2026-3655CRITICAL9.8The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in version...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now